I guess I'll start with a couple of details. A friend let me borrow his USB pen drive the other day so I could print some files. When I opened it I notices there were no files, but shortcuts to files. seemed odd but I opened it anyways and inside the shortcut were the files. He runs on Vista and I still run on XP so I thought it was something like that. Anyways, that was a couple of weeks back and nothing weird was happening. But one day I was charging my ipod and when I tried to eject, it gave me the "cannot eject, files are in use by another application" message. [Please note that it usually does that, even before all these problems started.] So I unplugged it anyways [which I admit I do sometimes] and when I tired listening to my songs, the ipod was blank. I tried to sync again but it wouldn't let me, then I tried to restore and it wouldn't let me. Right about this time was when my Avira caught the Jenxcus. So I read up on it and how it can corrupt hard-drives as well as the PC. So I started looking for a removal tool which I found
[the Microsoft removal tool], ran it and it supposedly got rid of it. So then to be sure I ran it again this time in safe mode and it showed the PC was clean. However, I'm scared of the ipod being corrupted now, and me letting in the worm again if I try to sync or do anything.
What can I do to make sure my system is completely clean, as well as my ipod and other pen drives I've used??
Thanks!!
help with jenxcus, maybe more [Solved]
18 min read
Hello Kilmez, welcome to WhatTheTech's Malware Removal forum!
My name is Adam. I will be assisting you with your malware-related problems.
If you would allow me to call you by your first name I would prefer that. ![]()
======================================================
From your post, I gather you have a Windows XP machine, iPod and at least one USB drive. Is this correct?
Are we dealing with just the one USB drive that belongs to your friend, or multiple USB drives?
For the time being, please limit use of your machine, and do not insert any additional devices into your computer.
Hi Adam. My given name is Juan. And yes, I run on XP and have an iPod that might be corrupted. As for the USB drive, I gave it back to my friend but I have another one that I know for sure I've used since. Don't worry, since all this went down, I haven't plugged in any other devices to my PC.
Hi Juan,
Concerning your friend's USB drive that you've given back - I suggest you inform your friend that the device is infected.
—
Please do the following.
As the USB drive you have access to may or may not be infected, we shall take a look at your computer first.
STEP 1
[external image: yFMlxsM.png] Disable AutoRun
- Please download and run this Microsoft Fixit to disable AutoRun.
- (Scroll down to: How to disable or enable all Autorun features in Windows 7 and other operating systems)
- Reboot your computer after running the Fixit.
STEP 2
[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Scan
- Please download Farbar Recovery Scan Tool (x32) and save the file to your Desktop.
- Right-Click FRST.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
- Click Yes to the disclaimer.
- Ensure the Addition.txt box is checked.
- Click the Scan button and let the programme run.
- Upon completion, click OK, then OK on the Addition.txt pop up screen.
- Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply.
======================================================
STEP 3
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.
- Did you successfully run the Microsoft Fixit?
- FRST.txt
- Addition.txt
Hi again Adam,
I have let my friend know about what my computer is doing and told him to watch out also.
Sorry I didn't reply sooner, but this is what happened.
I disabled the autorun like you told me, then I tried running Farbar but it didn't work. So I tied running it again and it worked this time,
but it never finished scaning. It got stuck. I didn't know if it was just my PC so I let it run for a bit hoping it would finish but it never did.
Eventually I got tired so I used ctrl+alt+del to end the process. After I did I ran Farbar once more and this time it worked and finished the scan very quickly.
Anyways, here are the logs:
FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by [removed] (administrator) on OWNER-XUKSZMPNK on 22-03-2015 22:19:04
Running from C:\Documents and Settings\[removed]\Desktop
[removed]
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(VIA Technologies, Inc.) C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Alcatel-Lucent) C:\Program Files\Common Files\Motive\McciCMService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(Yahoo! Inc.) C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [AudioDeck] => C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe [528384 2006-11-02] (VIA Technologies, Inc.)
HKLM\…\Run: [Start WingMan Profiler] => C:\PROGRAM FILES\Logitech\GAMING SOFTWARE\LWEMon.exe [88584 2008-04-04] (Logitech Inc.)
HKLM\…\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-02-13] (Apple Inc.)
HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.)
HKLM\…\Run: [Athan] => C:\Program Files\Athan\Athan.exe [1183744 2011-11-20] (www.IslamicFinder.org)
HKLM\…\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-05-19] (DivX, LLC)
HKLM\…\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1263952 2013-02-12] ()
HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\…\Run: [TkBellExe] => C:\Program Files\Real\RealPlayer\update\realsched.exe [295512 2013-08-02] (RealNetworks, Inc.)
HKLM\…\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2015-02-13] (Apple Inc.)
HKLM\…\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG)
HKLM\…\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [704512 2015-03-17] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-796845957-789336058-854245398-1003\…\Run: [OutfoxTV] => C:\Program Files\OutfoxTV\OutfoxTV\DesktopContainer.exe
HKU\S-1-5-21-796845957-789336058-854245398-1003\…\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6699800 2015-01-22] (SUPERAntiSpyware)
HKU\S-1-5-21-796845957-789336058-854245398-1003\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\System32\ssstars.scr [14336 2008-04-13] (Microsoft Corporation)
Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Amazon Cloud Drive.appref-ms ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-796845957-789336058-854245398-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
HKU\S-1-5-21-796845957-789336058-854245398-1003\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
URLSearchHook: HKU\S-1-5-21-796845957-789336058-854245398-1003 - YTNavAssist.YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll (Yahoo! Inc.)
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "http://www.outfox.tv/?referid="<======= ATTENTION
SearchScopes: HKLM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> URL http://search.conduit.com/Results.aspx?ctid=CT3324790&octid;=EB_ORIGINAL_CTID&SearchSource;=58&CUI;=&UM;=4&UP;=SPFD22E598-737F-4CA8-9084-DAAFFEE6F71D&q;={searchTerms}&SSPV;=
SearchScopes: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> SuggestionsURL_JSON http://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}
SearchScopes: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx?ctid=CT3324790&octid;=EB_ORIGINAL_CTID&SearchSource;=58&CUI;=&UM;=4&UP;=SPFD22E598-737F-4CA8-9084-DAAFFEE6F71D&q;={searchTerms}&SSPV;=
SearchScopes: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> {71F6384E-65C2-4090-B9BE-F3F3ABCA35FC} URL = http://rover.ebay.com/rover/1/711-43047-14818-1/4?satitle={searchTerms}
SearchScopes: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> {73EF2913-7B1D-4E29-A0BD-52D63C98462D} URL = http://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
SearchScopes: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> {AEEAA259-46E5-4A5B-9BAE-720EE287A92D} URL = http://en.wikipedia.org/w/index.php?title=Special:Search&search;={searchTerms}
SearchScopes: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> {D1469EE8-D1C0-4159-BDEA-568CBF0BA63B} URL = http://www.amazon.com/s?ie=UTF8&tag;=amznsearch.ms-20&index;=aps&link;%5Fcode=qs&field-keywords;={searchTerms}
SearchScopes: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> {E3A4EF04-FB86-45BC-B52A-C38E4B01C800} URL = http://www.youtube.com/results?search_query={searchTerms}
BHO: &Yahoo;! Toolbar Helper -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll [2011-09-24] (Yahoo! Inc.)
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-04-16] (RealDownloader)
BHO: DivX Plus Web Player HTML5 -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2013-05-06] (DivX, LLC)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-12-18] (Oracle Corporation)
BHO: WordExtra -> {8BA97046-C600-4264-B367-5DEFD9FC505F} -> C:\Documents and Settings\Owner\Application Data\WordExtra\temp.dat [2013-11-13] ()
BHO: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-12-18] (Oracle Corporation)
BHO: SingleInstance Class -> {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} -> C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll [2011-09-24] (Yahoo! Inc)
Toolbar: HKLM - att.net Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll [2011-09-24] (Yahoo! Inc.)
Toolbar: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> No Name - {41545534-2D56-3700-76A7-7A786E7484D7} - No File
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {E0FEE963-BB53-4215-81AD-B28C77384644} https://pattcw.att.motive.com/wizlet/DSLActivation/static/installer/ATTInternetInstaller.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL [2000-04-19] (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [115440 2013-05-07] (SuperAdBlocker.com)
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default
FF DefaultSearchEngine: Google
FF DefaultSearchEngine.US: Google
FF SearchEngineOrder.1: Ask.com
FF Homepage: www.google.com/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll [2013-07-23] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw_1203133.dll [2013-06-26] (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @divx.com/DivX Content Upload Plugin,version=1.0.0 -> C:\Program Files\DivX\DivX Content Uploader\npUpload.dll [2007-10-19] (DivX,Inc.)
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 -> C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll No File
FF Plugin: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll [2013-05-06] (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2011-06-20] (DivX, LLC.)
FF Plugin: @ei.TotalRecipeSearch_14.com/Plugin -> C:\Program Files\TotalRecipeSearch_14EI\Installr\1.bin\NP14EISB.dll No File
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2009-09-17] (Google)
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2013-12-18] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-12-18] (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @Motive.com/NpMotive,version=1.0 -> C:\Program Files\Common Files\Motive\npMotive.dll [2010-04-30] (Alcatel-Lucent)
FF Plugin: @real.com/nppl3260;version=16.0.2.32 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [2013-08-02] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.2 -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-04-16] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.2 -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-04-16] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.2 -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-04-16] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpchromebrowserrecordext;version=15.0.6.14 -> C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll [2012-10-12] (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=15.0.6.14 -> C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll [2012-10-12] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.2.32 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll [2013-08-02] (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-04-16] (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=8 -> C:\Program Files\Google\Update\1.2.183.13\npGoogleOneClick8.dll [2009-11-14] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-12-21] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-796845957-789336058-854245398-1003: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll No File
FF Plugin HKU\S-1-5-21-796845957-789336058-854245398-1003: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101710.dll [2012-08-06] (Amazon.com, Inc.)
FF user.js: detected! => C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\user.js [2014-03-07]
FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\conduit-search.xml [2014-03-06]
FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\dictionarycom.xml [2013-12-04]
FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\imdb.xml [2008-06-19]
FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\urban-dictionary.xml [2008-04-21]
FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\yahoo-answers.xml [2008-08-23]
FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\youtube.xml [2012-01-27]
FF Extension: Avira Browser Safety - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\Extensions\[removed] [2015-03-19]
FF Extension: Xuxen - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\Extensions\[removed] [2012-01-27]
FF Extension: Aero Fox - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\Extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66} [2008-08-26]
FF Extension: Yahoo! Toolbar - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}(2) [2015-02-27]
FF Extension: Dallas Cowboys - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\Extensions\{769d93be-4857-11dc-8314-0800200c9a66} [2008-08-27]
FF Extension: Amazon Quick Search - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\Extensions\{dffa0a29-2400-4d34-b469-efe699ce0115} [2009-12-20]
FF Extension: Amazonbutton US - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\Extensions\[removed] [2012-01-27]
FF Extension: Add to Amazon Wish List Button - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\Extensions\[removed] [2014-10-20]
FF Extension: TVU Web Player - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\Extensions\[removed] [2012-02-01]
FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi [2012-02-01]
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-07-01]
FF HKLM\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-08-02]
FF HKLM\…\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013-07-15]
FF HKLM\…\Firefox\Extensions: [{FCE04E1F-9378-4f39-96F6-5689A9159E45}] - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
StartMenuInternet: FIREFOX.EXE - C:\Program Files\FireFox\firefox.exe
Chrome:
=======
CHR HKLM\…\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM\…\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-04-16]
CHR HKLM\…\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2013-05-06]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-07-22] (SUPERAntiSpyware.com)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [432888 2015-03-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [432888 2015-03-17] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2013-12-18] (Oracle Corporation)
R2 McciCMService; C:\Program Files\Common Files\Motive\McciCMService.exe [319488 2010-04-30] (Alcatel-Lucent) [File not signed]
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] ()
S2 OutfoxTvService; C:\Program Files\OutfoxTV\OutfoxTvService.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 ASPI; C:\WINDOWS\System32\DRIVERS\ASPI32.sys [16512 2002-07-17] (Adaptec) [File not signed]
R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [105864 2015-03-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\WINDOWS\System32\DRIVERS\avipbb.sys [136216 2015-03-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\WINDOWS\System32\DRIVERS\avkmgr.sys [37352 2015-03-17] (Avira Operations GmbH & Co. KG)
S3 DNINDIS5; C:\WINDOWS\System32\DNINDIS5.SYS [17149 2003-07-24] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
R3 gameenum; C:\WINDOWS\System32\DRIVERS\gameenum.sys [10624 2008-04-13] (Microsoft Corporation)
R0 Lbd; C:\WINDOWS\System32\DRIVERS\Lbd.sys [64288 2010-06-10] (Lavasoft AB)
R2 MDC8021X; C:\WINDOWS\System32\DRIVERS\mdc8021x.sys [15890 2006-11-21] (Meetinghouse Data Communications) [File not signed]
S3 MREMP50; C:\Program Files\Common Files\Motive\MREMP50.sys [21248 2010-04-30] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MRESP50; C:\Program Files\Common Files\Motive\MRESP50.sys [20096 2010-04-30] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
R3 ms_mpu401; C:\WINDOWS\System32\drivers\msmpu401.sys [2944 2001-08-17] (Microsoft Corporation)
S3 Ptserial; C:\WINDOWS\System32\DRIVERS\ptserial.sys [136136 2001-08-30] (PCTEL, INC.) [File not signed]
R3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2004-08-04] (Realtek Semiconductor Corporation)
R3 S3Psddr; C:\WINDOWS\System32\DRIVERS\s3gnbm.sys [167040 2004-03-02] (S3 Graphics, Inc.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 ssmdrv; C:\WINDOWS\System32\DRIVERS\ssmdrv.sys [28520 2015-03-17] (Avira GmbH)
R1 StarOpen; C:\WINDOWS\system32\Drivers\StarOpen.sys [5632 2009-06-25] () [File not signed]
R0 viaagp1; C:\WINDOWS\System32\DRIVERS\viaagp1.sys [27904 2003-07-02] (VIA Technologies, Inc.)
R3 VIAudio; C:\WINDOWS\System32\drivers\vinyl97.sys [203648 2006-10-09] (VIA Technologies, Inc.) [File not signed]
R0 videX32; C:\WINDOWS\System32\DRIVERS\videX32.sys [9728 2006-02-23] (VIA Technologies, Inc.)
R0 Vmodem; C:\WINDOWS\System32\DRIVERS\vmodem.sys [604253 2001-08-17] (PCTEL, INC.)
R0 Vpctcom; C:\WINDOWS\System32\DRIVERS\vpctcom.sys [397502 2001-08-17] (PCtel, Inc.)
R0 Vvoice; C:\WINDOWS\System32\DRIVERS\vvoice.sys [64605 2001-08-17] (PCtel, Inc.)
R3 WmBEnum; C:\WINDOWS\System32\drivers\WmBEnum.sys [19336 2008-01-24] (Logitech Inc.)
R3 WmFilter; C:\WINDOWS\System32\drivers\WmFilter.sys [28168 2008-01-24] (Logitech Inc.)
R3 WmVirHid; C:\WINDOWS\System32\drivers\WmVirHid.sys [14728 2008-01-24] (Logitech Inc.)
R3 WmXlCore; C:\WINDOWS\System32\drivers\WmXlCore.sys [48904 2008-01-24] (Logitech Inc.)
S3 AR5523; System32\DRIVERS\wg11tnd5.sys [X]
S3 ATHFMWDL; System32\Drivers\ATHFMWDL.sys [X]
S4 IntelIde; No ImagePath
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-22 22:19 - 2015-03-22 22:21 - 00025180 _____ () C:\Documents and Settings\Owner\Desktop\FRST.txt
2015-03-22 15:03 - 2015-03-22 20:21 - 00020173 _____ () C:\Documents and Settings\Owner\Desktop\Addition1.txt
2015-03-22 14:59 - 2015-03-22 15:03 - 00036821 _____ () C:\Documents and Settings\Owner\Desktop\FRST1.txt
2015-03-22 14:58 - 2015-03-22 22:19 - 00000000 ____D () C:\FRST
2015-03-22 14:35 - 2015-03-22 14:35 - 00655360 _____ () C:\Documents and Settings\Owner\Desktop\MicrosoftFixit50471.msi
2015-03-22 05:25 - 2015-03-22 05:25 - 01135104 _____ (Farbar) C:\Documents and Settings\Owner\Desktop\FRST.exe
2015-03-21 17:26 - 2015-03-21 17:27 - 00000000 ____D () C:\Program Files\FireFox
2015-03-20 12:29 - 2015-03-22 14:50 - 00000278 _____ () C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-796845957-789336058-854245398-1003.job
2015-03-19 18:25 - 2015-03-19 18:25 - 00086048 _____ () C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2015-03-19 17:28 - 2015-03-19 17:28 - 00000440 _____ () C:\Documents and Settings\Owner\Start Menu\Anti-Virus.lnk
2015-03-19 17:26 - 2015-03-19 17:28 - 00000440 _____ () C:\Documents and Settings\Owner\Desktop\Anti-Virus.lnk
2015-03-19 16:47 - 2015-03-17 13:02 - 00028520 _____ (Avira GmbH) C:\WINDOWS\system32\Drivers\ssmdrv.sys
2015-03-19 16:43 - 2015-03-17 13:01 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2015-03-19 16:43 - 2015-03-17 13:01 - 00105864 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2015-03-19 16:43 - 2015-03-17 13:01 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys
2015-03-19 15:32 - 2015-03-19 18:26 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Package Cache
2015-03-19 15:32 - 2015-03-19 17:06 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Avira
2015-03-19 15:32 - 2015-03-19 16:40 - 00000000 ____D () C:\Program Files\Avira
2015-03-19 15:32 - 2015-03-19 16:40 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Avira
2015-03-19 14:52 - 2015-03-19 14:58 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2015-03-19 14:47 - 2015-03-19 14:47 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-03-19 14:47 - 2015-03-19 14:47 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2015-03-19 14:47 - 2014-10-01 11:11 - 00054360 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-03-19 14:47 - 2014-10-01 11:11 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-03-19 13:50 - 2015-03-19 13:50 - 04515896 _____ (Avira Operations & Co. KG) C:\Documents and Settings\Owner\Desktop\avira_en_av_550b197dcfa72__wsm.exe
2015-03-19 13:37 - 2015-03-19 13:37 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\RealNetworks
2015-03-19 04:02 - 2015-03-19 04:02 - 00001542 _____ () C:\Documents and Settings\All Users\Desktop\iTunes.lnk
2015-03-19 04:02 - 2015-03-19 04:02 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
2015-03-19 03:58 - 2015-03-19 04:01 - 00000000 ____D () C:\Program Files\iTunes
2015-03-19 03:58 - 2015-03-19 03:58 - 00000000 ____D () C:\Program Files\iPod
2015-03-19 03:08 - 2015-03-19 03:08 - 00000666 _____ () C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
2015-03-19 02:30 - 2015-03-19 02:30 - 00000000 ____D () C:\Documents and Settings\Owner\Desktop\Gym
2015-03-19 02:18 - 2015-03-19 02:18 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
2015-03-18 14:40 - 2015-03-19 02:15 - 00000000 ____D () C:\Program Files\iPod(2)
2015-03-18 14:38 - 2015-03-19 04:01 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-03-18 14:38 - 2015-03-19 02:15 - 00000000 ____D () C:\Program Files\iTunes(2)
2015-03-17 16:18 - 2015-03-17 16:18 - 00000000 _____ () C:\WINDOWS\setuperr.log
2015-02-24 07:42 - 2015-03-19 04:09 - 00012052 _____ () C:\WINDOWS\setupapi.log
2015-02-23 07:06 - 2015-02-23 07:09 - 00000000 ____D () C:\Documents and Settings\Owner\Desktop\Golpe Avisa
2015-02-23 06:29 - 2015-02-23 06:34 - 00000000 ____D () C:\Documents and Settings\Owner\Desktop\Sincopa 5.1
2015-02-23 06:06 - 2015-02-23 06:09 - 00000000 ____D () C:\Documents and Settings\Owner\Desktop\Vol. IV
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-22 22:21 - 2011-11-13 17:46 - 00000000 ____D () C:\Documents and Settings\Owner\Local Settings\temp
2015-03-22 20:23 - 2012-05-05 15:14 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-03-22 14:50 - 2014-10-11 18:50 - 00000286 _____ () C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-796845957-789336058-854245398-1003.job
2015-03-22 14:50 - 2012-01-04 14:00 - 00000278 _____ () C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-796845957-789336058-854245398-1003.job
2015-03-22 14:44 - 2013-05-02 14:11 - 00000000 ____D () C:\Documents and Settings\Owner\Local Settings\Application Data\Deployment
2015-03-22 14:44 - 2006-11-21 23:52 - 01587690 _____ () C:\WINDOWS\WindowsUpdate.log
2015-03-22 14:43 - 2014-04-26 07:01 - 00000222 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2015-03-22 14:43 - 2010-04-03 21:33 - 00000236 _____ () C:\WINDOWS\Tasks\OGALogon.job
2015-03-22 14:43 - 2006-11-21 00:08 - 00000006 ___HC () C:\WINDOWS\Tasks\SA.DAT
2015-03-22 14:43 - 2006-11-20 18:00 - 00000159 ____C () C:\WINDOWS\wiadebug.log
2015-03-22 14:43 - 2006-11-20 18:00 - 00000049 ____C () C:\WINDOWS\wiaservc.log
2015-03-22 14:42 - 2001-08-23 07:00 - 00002206 ____C () C:\WINDOWS\system32\wpa.dbl
2015-03-22 14:41 - 2006-11-21 00:13 - 00032482 _____ () C:\WINDOWS\SchedLgU.Txt
2015-03-22 14:40 - 2006-11-21 00:15 - 00000278 __SHC () C:\Documents and Settings\Owner\ntuser.ini
2015-03-22 14:40 - 2006-11-21 00:15 - 00000000 ____D () C:\Documents and Settings\Owner
2015-03-22 12:01 - 2010-12-03 18:56 - 00026907 ____C () C:\WINDOWS\KB967715.log
2015-03-22 04:44 - 2006-11-21 21:24 - 00000000 ___RD () C:\Documents and Settings\Owner\Desktop\Pelon
2015-03-21 18:50 - 2012-01-04 14:00 - 00000286 _____ () C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-796845957-789336058-854245398-1003.job
2015-03-20 18:39 - 2014-09-07 17:33 - 00000000 ____D () C:\Documents and Settings\Owner\Desktop\Memes
2015-03-20 12:16 - 2009-03-06 11:10 - 00000178 __SHC () C:\Documents and Settings\Administrator\ntuser.ini
2015-03-19 17:27 - 2006-11-22 15:46 - 00000000 ___RD () C:\Documents and Settings\Owner\My Documents\Anti-Virus
2015-03-19 14:58 - 2010-03-05 20:45 - 00000000 ____D () C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2015-03-19 14:50 - 2010-03-05 20:46 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
2015-03-19 14:50 - 2008-11-14 23:34 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2015-03-19 14:47 - 2008-11-15 14:38 - 00000000 ____D () C:\Documents and Settings\Owner\Application Data\Malwarebytes
2015-03-19 14:47 - 2008-11-15 14:38 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Malwarebytes
2015-03-19 13:39 - 2011-11-13 17:46 - 00000000 ____D () C:\Documents and Settings\Administrator\Local Settings\temp
2015-03-19 13:33 - 2010-03-10 13:18 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\Mozilla
2015-03-19 03:58 - 2007-07-28 13:27 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-03-19 03:57 - 2014-03-10 14:26 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
2015-03-19 03:08 - 2012-01-27 19:06 - 00000672 _____ () C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
2015-03-19 02:42 - 2006-11-20 17:58 - 00566924 ____C () C:\WINDOWS\system32\PerfStringBackup.INI
2015-03-19 02:32 - 2009-03-06 11:10 - 00000000 ____D () C:\Documents and Settings\Administrator
2015-03-19 02:32 - 2006-11-21 00:13 - 00000000 __SHD () C:\Documents and Settings\NetworkService
2015-03-19 02:32 - 2006-11-21 00:13 - 00000000 __SHD () C:\Documents and Settings\LocalService
2015-03-19 02:31 - 2006-11-21 00:05 - 00000000 ____D () C:\WINDOWS\Registration
2015-03-19 02:26 - 2007-12-05 12:33 - 00000000 ____D () C:\Program Files\CD to MP3 Freeware
2015-03-19 02:18 - 2007-07-28 13:30 - 00000000 ____D () C:\Program Files\QuickTime
2015-03-19 01:41 - 2007-04-12 16:17 - 00000000 ____D () C:\WINDOWS\system32\NtmsData
2015-03-17 16:18 - 2010-08-23 21:11 - 00002411 _____ () C:\WINDOWS\setupact.log
2015-03-16 07:13 - 2012-11-28 01:39 - 00000000 ____D () C:\Documents and Settings\Owner\Desktop\New-Update
2015-03-16 07:06 - 2011-11-16 12:07 - 00000284 _____ () C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2015-03-16 04:11 - 2009-09-24 10:19 - 01132032 __SHC () C:\Documents and Settings\Owner\Desktop\Thumbs.db
2015-03-11 18:48 - 2006-11-22 19:19 - 119837704 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-03-08 18:30 - 2014-07-22 16:07 - 00000000 ____D () C:\Documents and Settings\Owner\Desktop\New Folder
2015-03-08 15:00 - 2014-04-26 07:01 - 00000216 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
==================== Files in the root of some directories =======
2006-12-12 17:48 - 2006-12-12 17:48 - 0000023 ____C () C:\Documents and Settings\Owner\Application Data\inifile41.ini
2006-12-12 17:48 - 2006-12-18 04:56 - 0000337 ____C () C:\Documents and Settings\Owner\Application Data\internaldb1942.dat
2006-12-12 17:49 - 2006-12-19 01:07 - 0000049 ____C () C:\Documents and Settings\Owner\Application Data\internaldb41.dat
2006-12-12 17:48 - 2006-12-12 17:49 - 0020480 ____C () C:\Documents and Settings\Owner\Application Data\internaldb4827.dat
2006-12-12 17:48 - 2006-12-12 17:48 - 0000000 ____C () C:\Documents and Settings\Owner\Application Data\internaldb5436.dat
2006-12-12 17:49 - 2006-12-12 17:49 - 0000000 ____C () C:\Documents and Settings\Owner\Application Data\internaldb6334.dat
2006-12-12 17:49 - 2006-12-12 17:49 - 0009216 ____C () C:\Documents and Settings\Owner\Application Data\internaldb8467.dat
2006-11-21 23:47 - 2014-12-16 17:45 - 0121344 _____ () C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
Some content of TEMP:
====================
C:\Documents and Settings\Owner\Local Settings\temp\AskSLib.dll
C:\Documents and Settings\Owner\Local Settings\temp\avgnt.exe
C:\Documents and Settings\Owner\Local Settings\temp\jre-8u40-windows-au.exe
C:\Documents and Settings\Owner\Local Settings\temp\sqlite-3.7.2-sqlitejdbc.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================
Addition.txt
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-03-2015
Ran by [removed] at 2015-03-22 22:23:56
Running from C:\Documents and Settings\[removed]\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Desktop (Disabled - Up to date) {AD166499-45F9-482A-A743-FDD3350758C7}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe AIR (HKLM\…\Adobe AIR) (Version: 3.4.0.2540 - Adobe Systems Incorporated)
Adobe Flash Player 11 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 11.4.402.287 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (HKLM\…\Adobe Flash Player Plugin) (Version: 11.8.800.94 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM\…\Adobe Shockwave Player) (Version: 12.0.3.133 - Adobe Systems, Inc.)
Amazon Cloud Drive (HKU\S-1-5-21-796845957-789336058-854245398-1003\…\23ab716f18849b6f) (Version: 2.4.2013.3290 - Amazon)
Amazon MP3 Downloader 1.0.17 (HKLM\…\Amazon MP3 Downloader) (Version: 1.0.17 - Amazon Services LLC)
Apple Application Support (32-bit) (HKLM\…\{447CDCE5-F555-429B-BFA6-642C3C6D684F}) (Version: 3.1.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{E1DB0812-2D60-43DB-AE09-6C7027D93B28}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AT&T; Internet Security Wizard 1.5.11 (HKLM\…\RadialpointClientGateway_is1) (Version: 1.5.11 - AT&T;)
AT&T; Toolbar (HKLM\…\ATTToolbar) (Version: - )
Athan Basic 4.2 (HKLM\…\Athan) (Version: - )
AtomixMP3 v2.3 Trial (HKLM\…\AtomixMP3 v2.3 Trial) (Version: - )
att.net Internet Mail (HKLM\…\Yahoo! Mail) (Version: - )
att.net Toolbar (HKLM\…\Yahoo! Companion) (Version: - att.net)
ATT-HSI (HKLM\…\ATT-HSI) (Version: - )
aTube Catcher version 3.8 (HKLM\…\{D43B360E-722D-421B-BC77-20B9E0F8B6CD}_is1) (Version: 3.8 - DsNET Corp)
Avira (HKLM\…\{bd538030-07d4-4999-a525-7fafa2483f56}) (Version: 1.1.30.21727 - Avira Operations & Co. KG)
Avira (Version: 1.1.30.21727 - Avira Operations & Co. KG) Hidden
Avira Free Antivirus (HKLM\…\Avira AntiVir Desktop) (Version: 15.0.8.656 - Avira)
Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Compatibility Pack for the 2007 Office system (HKLM\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
DivX Converter (HKLM\…\{13F3917B56CD4C25848BDC69916971BB}) (Version: 7.0.0 - DivX, Inc.)
DivX Converter (HKLM\…\{B13A7C41581B411290FBC0395694E2A9}) (Version: 7.0.0 - DivX, Inc.)
DivX Setup (HKLM\…\DivX Setup) (Version: 2.6.1.44 - DivX, LLC)
DivX Version Checker (HKLM\…\{3FC7CBBC4C1E11DCA1A752EA55D89593}) (Version: 7.0.0.19 - DivX, Inc.)
Easy Unit Converter (HKLM\…\Easy Unit Converter) (Version: 1.2 - FilesWeb.com)
eMule (HKLM\…\eMule) (Version: - )
ffdshow v1.1.3351 [2010-04-08] (HKLM\…\ffdshow_is1) (Version: 1.1.3351.0 - )
Final Fantasy VII - Ultima Edition (HKLM\…\Final Fantasy VII_is1) (Version: - )
FLAC 1.2.1b (remove only) (HKLM\…\FLAC) (Version: 1.2.1b - Xiph.org)
FLVPlayer4Free Free FLV Player 4.7.0.0 (HKLM\…\FLVPlayer4Free Free FLV Player_is1) (Version: - Sakysoft s.r.l. uninominale) <==== ATTENTION
FM Screen Capture Codec (Remove Only) (HKLM\…\FMCODEC) (Version: - )
Free CD to MP3 Converter (HKLM\…\Free CD to MP3 Converter) (Version: - )
Google Earth (HKLM\…\{3A05B900-A3E7-11DE-A9B7-005056806466}) (Version: 5.1.3509.4636 - Google)
GSpot Codec Information Appliance (HKLM\…\GSpot) (Version: - )
HSP56 MR Drivers (HKLM\…\Installing HSP56 MicroModem Drivers) (Version: - )
IMDb Toolbar (HKLM\…\IMDb Toolbar) (Version: - Adds IMDb Content to Internet Explorer)
Indeo Codecs (HKLM\…\indeocodecs_is1) (Version: 1.1 - )
iTunes (HKLM\…\{3A9FE6B1-EE7F-40AC-B831-AC7C9ABB58A0}) (Version: 12.1.1.4 - Apple Inc.)
Java 7 Update 51 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.510 - Oracle)
K-Lite Codec Pack 4.1.6 (Full) (HKLM\…\KLiteCodecPack_is1) (Version: 4.1.6 - )
Logitech Gaming Software 5.02 (HKLM\…\{64B20B36-AEE7-4DD4-897C-C5DA5C218F60}) (Version: 5.02.116 - Logitech)
Malwarebytes Anti-Malware version 2.0.3.1025 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation)
Microsoft .NET Framework 1.1 (HKLM\…\Microsoft .NET Framework 1.1 (1033)) (Version: - )
Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\…\M2698023) (Version: - )
Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\…\M2833941) (Version: - )
Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\…\M979906) (Version: - )
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\…\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\…\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\…\MSCompPackV1) (Version: 1 - Microsoft Corporation)
Microsoft Office XP Professional with FrontPage (HKLM\…\{90280409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)
Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\…\Wudf01000) (Version: - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\…\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Windows Media Video 9 VCM (HKLM\…\WMV9_VCM) (Version: - )
Mozilla Firefox 36.0.4 (x86 en-US) (HKLM\…\Mozilla Firefox 36.0.4 (x86 en-US)) (Version: 36.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 36.0.1 - Mozilla)
Nero OEM (HKLM\…\Nero - Burning Rom!UninstallKey) (Version: - )
Next Video Converter 2.6.0 (HKLM\…\{2AD89908-0987-4B9E-8AB4-905899E4D754}_is1) (Version: - NextVideoSoft, Inc.)
OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0 - Microsoft Corporation) Hidden
PC Inspector File Recovery (HKLM\…\{0DD140D3-9563-481E-AA75-BA457CBDAEF2}) (Version: 4.0 - )
QuickTime (HKLM\…\{7BE15435-2D3E-4B58-867F-9C75BED0208C}) (Version: 7.71.80.42 - Apple Inc.)
RealDownloader (Version: 1.3.2 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM\…\RealPlayer 16.0) (Version: 16.0.2 - RealNetworks)
RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
S3Display (HKLM\…\S3Display) (Version: - )
S3Gamma2 (HKLM\…\S3Gamma2) (Version: - )
S3Info2 (HKLM\…\S3Info2) (Version: - )
S3Overlay (HKLM\…\S3Overlay) (Version: - )
Segoe UI (Version: 14.0.4327.805 - Microsoft Corp) Hidden
SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1170 - SUPERAntiSpyware.com)
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Ulead GIF Animator 2.0 Full Version (HKLM\…\Ulead GIF Animator 2.0 Full Version) (Version: - )
VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden
VideoLAN VLC media player 0.8.6b (HKLM\…\VLC media player) (Version: 0.8.6b - VideoLAN Team)
Visual C++ 2008 x86 Runtime - v9.0.30729.01 (HKLM\…\{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01) (Version: 9.0.30729.01 - Microsoft Corporation)
WebFldrs XP (Version: 9.50.6513 - Microsoft Corporation) Hidden
Windows Genuine Advantage Notifications (KB905474) (HKLM\…\WgaNotify) (Version: 1.7.0018.7 - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\…\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Live Essentials (HKLM\…\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live Sign-in Assistant (HKLM\…\{9422C8EA-B0C6-4197-B8FC-DC797658CA00}) (Version: 5.000.818.6 - Microsoft Corporation)
Windows Live Upload Tool (HKLM\…\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
Windows Media Format 11 runtime (HKLM\…\Windows Media Format Runtime) (Version: - )
Windows Media Player Firefox Plugin (HKLM\…\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
Windows XP Service Pack 3 (HKLM\…\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
WinRAR archiver (HKLM\…\WinRAR archiver) (Version: - )
Wondershare Data Recovery 1.5.0 (HKLM\…\Wondershare Data Recovery_is1) (Version: - )
WordExtra (HKU\S-1-5-21-796845957-789336058-854245398-1003\…\WordExtra) (Version: 1 - http://www.wordextra.com)
Xvid 1.1.3 final uninstall (HKLM\…\Xvid_is1) (Version: 1.1 - Xvid team (Koepi))
Yahoo! Software Update (HKLM\…\Yahoo! Software Update) (Version: - )
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-796845957-789336058-854245398-1003_Classes\CLSID\{3f04dadf-6ea4-44d1-a507-03cad176f443}\InprocServer32 -> C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101710.dll (Amazon.com, Inc.)
==================== Restore Points =========================
22-12-2014 23:52:34 System Checkpoint
24-12-2014 00:52:39 System Checkpoint
25-12-2014 04:10:15 System Checkpoint
26-12-2014 04:53:02 System Checkpoint
27-12-2014 05:02:47 System Checkpoint
28-12-2014 05:52:53 System Checkpoint
29-12-2014 07:02:11 System Checkpoint
30-12-2014 07:54:09 System Checkpoint
31-12-2014 12:26:58 System Checkpoint
01-01-2015 12:53:10 System Checkpoint
02-01-2015 13:52:56 System Checkpoint
03-01-2015 14:51:36 System Checkpoint
04-01-2015 15:51:40 System Checkpoint
06-01-2015 08:50:24 System Checkpoint
07-01-2015 17:20:43 System Checkpoint
09-01-2015 09:36:52 System Checkpoint
10-01-2015 10:20:14 System Checkpoint
11-01-2015 10:51:43 System Checkpoint
12-01-2015 11:51:41 System Checkpoint
13-01-2015 12:04:17 System Checkpoint
14-01-2015 16:32:00 System Checkpoint
15-01-2015 17:14:17 System Checkpoint
17-01-2015 05:37:00 System Checkpoint
18-01-2015 06:17:19 System Checkpoint
19-01-2015 08:29:02 System Checkpoint
20-01-2015 09:37:03 System Checkpoint
21-01-2015 09:52:10 System Checkpoint
22-01-2015 10:51:53 System Checkpoint
23-01-2015 11:52:03 System Checkpoint
24-01-2015 12:49:55 System Checkpoint
25-01-2015 16:02:54 System Checkpoint
26-01-2015 18:07:48 System Checkpoint
27-01-2015 18:09:19 System Checkpoint
28-01-2015 18:11:39 System Checkpoint
30-01-2015 18:13:27 System Checkpoint
31-01-2015 18:53:03 System Checkpoint
01-02-2015 19:03:31 System Checkpoint
02-02-2015 21:53:59 System Checkpoint
04-02-2015 03:17:05 System Checkpoint
05-02-2015 09:02:02 System Checkpoint
06-02-2015 09:50:06 System Checkpoint
07-02-2015 13:58:08 System Checkpoint
08-02-2015 14:49:29 System Checkpoint
09-02-2015 16:22:51 System Checkpoint
10-02-2015 17:09:42 System Checkpoint
11-02-2015 20:14:11 System Checkpoint
12-02-2015 20:49:21 System Checkpoint
13-02-2015 21:49:27 System Checkpoint
15-02-2015 23:53:57 System Checkpoint
17-02-2015 00:49:26 System Checkpoint
18-02-2015 01:38:50 System Checkpoint
20-02-2015 16:54:30 System Checkpoint
21-02-2015 19:06:16 System Checkpoint
22-02-2015 19:49:29 System Checkpoint
23-02-2015 20:16:59 System Checkpoint
24-02-2015 20:31:07 System Checkpoint
25-02-2015 21:17:06 System Checkpoint
26-02-2015 22:16:52 System Checkpoint
27-02-2015 23:16:50 System Checkpoint
01-03-2015 00:16:45 System Checkpoint
02-03-2015 02:34:09 System Checkpoint
03-03-2015 03:16:36 System Checkpoint
04-03-2015 10:07:58 System Checkpoint
05-03-2015 10:53:56 System Checkpoint
06-03-2015 16:07:14 System Checkpoint
07-03-2015 16:16:43 System Checkpoint
08-03-2015 16:38:08 System Checkpoint
10-03-2015 02:49:51 System Checkpoint
11-03-2015 03:41:42 System Checkpoint
12-03-2015 04:39:25 System Checkpoint
13-03-2015 05:38:17 System Checkpoint
14-03-2015 06:38:35 System Checkpoint
15-03-2015 06:50:59 System Checkpoint
16-03-2015 07:40:47 System Checkpoint
17-03-2015 08:23:13 System Checkpoint
18-03-2015 11:09:24 System Checkpoint
19-03-2015 02:10:59 Restore Operation
19-03-2015 03:55:15 Installed iTunes
19-03-2015 14:50:23 Removed SUPERAntiSpyware Free Edition
20-03-2015 15:38:24 System Checkpoint
21-03-2015 16:33:29 System Checkpoint
22-03-2015 05:31:47 Installed Windows XP KB967715.
22-03-2015 14:38:21 Installed Microsoft Fix it 50471
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2001-08-23 07:00 - 2011-11-13 17:36 - 00000027 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\AppleSoftwareUpdate.job => C:\Program Files\Apple Software Update\SoftwareUpdate.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\OGALogon.job => C:\WINDOWS\system32\OGAEXEC.exe
Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-796845957-789336058-854245398-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-796845957-789336058-854245398-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-796845957-789336058-854245398-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-796845957-789336058-854245398-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
==================== Loaded Modules (whitelisted) ==============
2006-11-21 01:15 - 2006-09-14 01:20 - 00126464 _____ () C:\Program Files\WinRAR\rarext.dll
2013-02-12 21:37 - 2013-02-12 21:37 - 01263952 _____ () C:\Program Files\DivX\DivX Update\DivXUpdate.exe
2013-02-12 21:38 - 2013-02-12 21:38 - 00100688 _____ () C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
2014-02-12 20:58 - 2014-02-12 20:58 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-02-13 04:20 - 2015-02-13 04:20 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-01-19 12:03 - 2015-01-19 12:03 - 00245760 _____ () C:\Program Files\Avira\My Avira\System.ComponentModel.Composition.dll
2013-04-16 03:07 - 2013-04-16 03:07 - 00039056 _____ () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-796845957-789336058-854245398-1003\Control Panel\Desktop\\Wallpaper -> C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
DNS Servers: 192.168.1.254
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WG111T Smart Wizard.lnk => C:\WINDOWS\pss\NETGEAR WG111T Smart Wizard.lnkCommon Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: ISW.exe => "C:\Program Files\AT&T;\Internet Security Wizard\ISW.exe" /AUTORUN
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: KernelFaultCheck => %systemroot%\system32\dumprep 0 -k
MSCONFIG\startupreg: MSMSGS => "C:\Program Files\Messenger\msmsgs.exe" /background
MSCONFIG\startupreg: NeroFilterCheck => C:\WINDOWS\system32\NeroCheck.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: TkBellExe => "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
MSCONFIG\startupreg: VTPreset => VTPreset.exe
==================== Accounts: =============================
Administrator (S-1-5-21-796845957-789336058-854245398-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator
ASPNET (S-1-5-21-796845957-789336058-854245398-1005 - Limited - Enabled)
Guest (S-1-5-21-796845957-789336058-854245398-501 - Limited - Enabled)
HelpAssistant (S-1-5-21-796845957-789336058-854245398-1000 - Limited - Disabled)
Owner (S-1-5-21-796845957-789336058-854245398-1003 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Owner
SUPPORT_388945a0 (S-1-5-21-796845957-789336058-854245398-1002 - Limited - Disabled)
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (03/22/2015 08:21:05 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application FRST.exe, version 11.3.2015.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (03/22/2015 02:51:02 PM) (Source: .NET Runtime 2.0 Error Reporting) (EventID: 5000) (User: )
Description: EventType clr20r3, P1 amazonclouddrive.exe, P2 2.0.0.0, P3 5293b4d5, P4 system.security, P5 2.0.0.0, P6 51d3d066, P7 c2, P8 e2, P9 clr20r30, P10 clr20r31.
Error: (03/20/2015 00:41:40 PM) (Source: .NET Runtime 2.0 Error Reporting) (EventID: 5000) (User: )
Description: EventType clr20r3, P1 amazonclouddrive.exe, P2 2.0.0.0, P3 5293b4d5, P4 system.security, P5 2.0.0.0, P6 51d3d066, P7 c2, P8 e2, P9 clr20r30, P10 clr20r31.
Error: (03/19/2015 01:42:26 PM) (Source: Avira AntiVir) (EventID: 4109) (User: NT AUTHORITY)
Description: 0x9
Error: (03/19/2015 04:23:05 AM) (Source: Avira AntiVir) (EventID: 4109) (User: NT AUTHORITY)
Description: 0x9
Error: (03/19/2015 04:16:34 AM) (Source: Avira AntiVir) (EventID: 4109) (User: NT AUTHORITY)
Description: 0x9
Error: (03/19/2015 04:15:59 AM) (Source: Avira AntiVir) (EventID: 4109) (User: NT AUTHORITY)
Description: 0x9
Error: (03/19/2015 04:15:02 AM) (Source: Avira AntiVir) (EventID: 4109) (User: NT AUTHORITY)
Description: 0x9
Error: (03/19/2015 03:12:30 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application rundll32.exe, version 5.1.2600.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (03/19/2015 02:34:47 AM) (Source: Avira AntiVir) (EventID: 4109) (User: NT AUTHORITY)
Description: 0x9
System errors:
=============
Error: (03/20/2015 00:19:18 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The OutfoxTvService service failed to start due to the following error:
%%2
Error: (03/20/2015 00:19:18 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Wireless Zero Configuration service depends on the NDIS Usermode I/O Protocol service which failed to start because of the following error:
%%1058
Error: (03/20/2015 00:16:39 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}
Error: (03/17/2015 08:59:07 AM) (Source: 0) (EventID: 11) (User: )
Description: \Device\Harddisk1\D
Error: (03/17/2015 08:55:27 AM) (Source: 0) (EventID: 11) (User: )
Description: \Device\Harddisk1\D
Error: (03/17/2015 08:55:26 AM) (Source: 0) (EventID: 11) (User: )
Description: \Device\Harddisk1\D
Error: (03/17/2015 08:55:25 AM) (Source: 0) (EventID: 11) (User: )
Description: \Device\Harddisk1\D
Error: (03/17/2015 08:55:24 AM) (Source: 0) (EventID: 11) (User: )
Description: \Device\Harddisk1\D
Error: (03/17/2015 08:55:23 AM) (Source: 0) (EventID: 11) (User: )
Description: \Device\Harddisk1\D
Error: (03/17/2015 08:55:22 AM) (Source: 0) (EventID: 11) (User: )
Description: \Device\Harddisk1\D
Microsoft Office Sessions:
=========================
Error: (03/22/2015 08:21:05 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: FRST.exe11.3.2015.0hungapp0.0.0.000000000
Error: (03/22/2015 02:51:02 PM) (Source: .NET Runtime 2.0 Error Reporting) (EventID: 5000) (User: )
Description: clr20r3amazonclouddrive.exe2.0.0.05293b4d5system.security2.0.0.051d3d066c2e2udta330idobh2roz2ayvlcelag5agtlsNIL
Error: (03/20/2015 00:41:40 PM) (Source: .NET Runtime 2.0 Error Reporting) (EventID: 5000) (User: )
Description: clr20r3amazonclouddrive.exe2.0.0.05293b4d5system.security2.0.0.051d3d066c2e2udta330idobh2roz2ayvlcelag5agtlsNIL
Error: (03/19/2015 01:42:26 PM) (Source: Avira AntiVir) (EventID: 4109) (User: NT AUTHORITY)
Description: 0x9
Error: (03/19/2015 04:23:05 AM) (Source: Avira AntiVir) (EventID: 4109) (User: NT AUTHORITY)
Description: 0x9
Error: (03/19/2015 04:16:34 AM) (Source: Avira AntiVir) (EventID: 4109) (User: NT AUTHORITY)
Description: 0x9
Error: (03/19/2015 04:15:59 AM) (Source: Avira AntiVir) (EventID: 4109) (User: NT AUTHORITY)
Description: 0x9
Error: (03/19/2015 04:15:02 AM) (Source: Avira AntiVir) (EventID: 4109) (User: NT AUTHORITY)
Description: 0x9
Error: (03/19/2015 03:12:30 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: rundll32.exe5.1.2600.5512hungapp0.0.0.000000000
Error: (03/19/2015 02:34:47 AM) (Source: Avira AntiVir) (EventID: 4109) (User: NT AUTHORITY)
Description: 0x9
==================== Memory info ===========================
Processor: Intel(R) Pentium(R) 4 CPU 1400MHz
Percentage of memory in use: 32%
Total physical RAM: 735.48 MB
Available physical RAM: 496.93 MB
Total Pagefile: 1266.14 MB
Available Pagefile: 674.47 MB
Total Virtual: 2047.88 MB
Available Virtual: 1944.98 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:111.78 GB) (Free:18.27 GB) NTFS ==>[Drive with boot components (Windows XP)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 111.8 GB) (Disk ID: 40E340E2)
Partition 1: (Active) - (Size=111.8 GB) - (Type=07 NTFS)
==================== End Of Log ============================
Thanks!!
Hello Juan,
I'm not seeing any malware on your computer - only adware. Are any of your security programmes still flagging Jenxcus?
We need to take a look at the USB you mentioned was inserted into your computer recently. This device could be infected, but the steps I've provided will ensure you can safely insert into your computer.
Before proceeding, please consider the following warnings. Read the articles linked, and let me know if you have any questions.
Don't forget to answer my two questions below as well.
[external image: goGMWSt.gif]Unsupported Operating System Notice
——————————
On April 8th 2014, Microsoft officially declared Windows XP as unsupported, and consequently ceased the production and release of Windows XP Updates and Security Patches. Please refer to the following articles for more information.Without Windows Updates, your computer will be continuously susceptible to malware infection. In the past, vulnerabilities found in the Windows XP software were patched shortly after by Microsoft issuing an Update. Now that XP is no long supported with Updates, once a vulnerability is discovered, it will not be patched; allowing malware authors to freely distribute their exploit in the knowledge the vulnerability will not be patched. Keeping an Internet-connected Windows XP machine free of malware is unpractical. The only solution is to upgrade to a supported Operating System (Windows Vista/7/8).
- End Of Support For Windows XP SP3 is April 8, 2014
- Windows XP - The Elephant In The Room
- With XP ending, what are your alternatives?
Please let me know if you have any questions.
[external image: goGMWSt.gif]P2P Warning
——————————
I see you have peer-to-peer (P2P) file sharing software installed on your computer (eMule). I advise you avoid P2P file sharing programmes; they are a security risk which can make your computer susceptible to malware. File sharing networks are thoroughly infested with malware - worms, backdoor Trojans, IRCBots, and rootkits propagate via P2P file sharing networks, gaming, and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install malware. The best way to reduce the risk of infection is to avoid these types of web sites and P2P programmes. Please read the following articles for more information.Your P2P software can be removed by following the instructions below.
- Risks of File-Sharing Technology
- P2P Software User Advisories
- More malware is traveling on P2P networks these days
If you choose not to, please refrain from using the programme(s) during this process.
- Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type appwiz.cpl and click OK.
- Search for the aforementioned programme(s), right-click and click Uninstall. Follow the prompts.
—
Do you recognise this shortcut on your Desktop? Is this related to Avira? C:\Documents and Settings\Owner\Desktop\Anti-Virus.lnk
Do you recognise this folder? C:\Documents and Settings\Owner\Desktop\Pelon
—
STEP 1
[external image: ypeNg1J.png] Panda USB Vaccine
- Please download Panda USB Vaccine and save the file to your Desktop.
- Double-Click USBVaccineSetup.exe to install the programme.
- Read and accept the license agreement, then click Next.
- Upon completion of the setup, ensure Launch Panda USB Vaccine is checked and click Finish.
- Click the Vaccinate Computer button. It should now show a green checkmark and confirm Computer vaccinated.
- Hold down the Shift key on your keyboard and insert your USB flash/external drive.
- When the name of the drive appears in the Panda USB Vaccine dialog box, click the Vaccinate USB drive(s) button.
- Exit the programme when done.
– Computer Vaccination will prevent any AutoRun file from running, regardless of whether the removable device is infected or not. USB Vaccination disables the autorun file so it cannot be read, modified or replaced and creates an AUTORUN_.INF as protection against malicious code. The Panda Resarch Blog advises that once USB drives have been vaccinated, they cannot be reversed except with a format. If you do this, be sure to back up your data files first or they will be lost during the formatting process.
STEP 2
[external image: nSymGHK.png] Folder Options
- Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Control Folders and click OK.
- Click View. Under Hidden files and folders:
- Place a checkmark next to Show hidden files, folders and drives.
- Remove the checkmark next to Hide extensions for known file types.
- Remove the checkmark next to Hide protected operating system Files (Recommended).
- Click Apply followed by OK.
STEP 3
[external image: nQPbWA9.png] USBFix Research
- Please download USBFix and save the file to your Desktop.
- Note: The website is in Spanish. Click Descagar to download.
- Double-Click USBFix.exe to run the programme.
- Follow the prompts.
- Click Options. Place a checkmark next to Listing + and click Apply.
- Ensure your USB drive is inserted into your PC and click Research.
- A log (C:\UsbFix [Scan 1] username.txt) will be created. Copy the contents of the log and paste in your next reply.
- Note: username corresponds to the username of your current profile.
STEP 4
[external image: nQPbWA9.png] USBFix Listing
- Ensure the infected USB is still inserted in your PC.
- Click Listing.
- A log (C:\UsbFix [Listing 1] username.txt) will be created. Copy the contents of the log and paste in your next reply.
- Note: username corresponds to the username of your current profile.
======================================================
STEP 5
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.
- Do you have any questions concerning the two warnings?
- Answers to questions
- Did Panda USB Vaccine run successfully?
- C:\UsbFix [Scan 1] username.txt
- C:\UsbFix [Listing 1] username.txt
Hi again..
Well I know I should upgrade, but truth is I've tried Vista, 7, 8, etc. and I really don't like them.
I guess eventually I will have to, but I'm gonna hold off a bit. eMule I hardly use anymore,
I just use it very sporadically and when I do I'm very careful about what I get.
About the 2 folders:
C:\Documents and Settings\Owner\Desktop\Anti-Virus.lnk
C:\Documents and Settings\Owner\Desktop\Pelon
yes I recognize them both. C:\Documents and Settings\Owner\Desktop\Anti-Virus.lnk
is just a shortcut I have on the desktop where I keep MalwareBytes, Avira, etc.
the other one Is for all my files.
Also, Avira has not flagged the Jenxcus anymore.
Panda Vaccine never vaccinated the USB. It vaccinated the computer, but when I try to vaccinate the USB it just stays stuck
and shows the sandclock.
Anything else I can do??
Can I maybe just reformat the USB while the computer is vaccinated?? I really don't have any use for any of the files on there.
Thanks for the information.
I can appreciate what you're saying. Familiarity is a important factor involved in the decision process. Ultimately, you need to decide whether you value familiarity or security more. Nowadays, malware is a multi-billion "industry", and will only continue to grow.I've tried Vista, 7, 8, etc. and I really don't like them.
Absolutely. Reformatting the device is the best option.Can I maybe just reformat the USB while the computer is vaccinated??
If you choose to do this, you don't need to run USBFix.
Let me know when you've reformatted the USB drive, and we'll go from there.
Thanks for your help Adam. I just finished reformatting the USB.
Let me know what comes next. ![]()
Hello Juan,
I just finished reformatting the USB.
Good job.
Lets continue.
STEP 1
[external image: 6JO0hXH.png] Revo Uninstaller
- Please download and install Revo Uninstaller.
- Double-Click Revo Uninstaller to run the programme.
- From the list of programmes, locate the following, or anything similar and carry out the steps below one at a time.
- FLVPlayer4Free Free FLV Player 4.7.0.0
- WordExtra
- Double-Click the programme.
- When prompted if you want to uninstall click Yes.
- Ensure the Moderate option is selected and click Next.
- The programme uninstaller will run. If prompted again click Yes.
- Work your way through the uninstaller, ensuring you read each page thoroughly.
- Note: If you are offered the choice to install additional software, ensure you decline.
- Once the built-in uninstaller is finished click Next.
- Once the programme has searched for leftovers click Next.
- Check items in bold only in the list and click Delete. You may have to expand folders by clicking the "+" mark.
- When prompted click Yes, followed by Next.
- Click Select all, followed by Delete.
- When prompted click Yes, followed by Next.
- Upon completion, click Finish.
- In your next reply, confirm you were successful in uninstalling all programmes listed above.
STEP 2
[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Script
- Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
- Copy the entire contents of the codebox below and paste into the Notepad document.
start CreateRestorePoint: HKU\S-1-5-21-796845957-789336058-854245398-1003\…\Run: [OutfoxTV] => C:\Program Files\OutfoxTV\OutfoxTV\DesktopContainer.exe C:\Program Files\OutfoxTV HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-796845957-789336058-854245398-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "http://www.outfox.tv/?referid="<======= ATTENTION SearchScopes: HKLM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = SearchScopes: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> URL http://search.condui…rchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> SuggestionsURL_JSON http://suggest.searc…x={searchTerms} SearchScopes: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.condui…rchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> {73EF2913-7B1D-4E29-A0BD-52D63C98462D} URL = http://search.yahoo….=utf-8&fr=b1ie7 BHO: WordExtra -> {8BA97046-C600-4264-B367-5DEFD9FC505F} -> C:\Documents and Settings\Owner\Application Data\WordExtra\temp.dat [2013-11-13] () C:\Documents and Settings\Owner\Application Data\WordExtra Toolbar: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> No Name - {41545534-2D56-3700-76A7-7A786E7484D7} - No File FF SearchEngineOrder.1: Ask.com FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\conduit-search.xml [2014-03-06] S2 OutfoxTvService; C:\Program Files\OutfoxTV\OutfoxTvService.exe [X] 2006-12-12 17:48 - 2006-12-12 17:48 - 0000023 ____C () C:\Documents and Settings\Owner\Application Data\inifile41.ini 2006-12-12 17:48 - 2006-12-18 04:56 - 0000337 ____C () C:\Documents and Settings\Owner\Application Data\internaldb1942.dat 2006-12-12 17:49 - 2006-12-19 01:07 - 0000049 ____C () C:\Documents and Settings\Owner\Application Data\internaldb41.dat 2006-12-12 17:48 - 2006-12-12 17:49 - 0020480 ____C () C:\Documents and Settings\Owner\Application Data\internaldb4827.dat 2006-12-12 17:48 - 2006-12-12 17:48 - 0000000 ____C () C:\Documents and Settings\Owner\Application Data\internaldb5436.dat 2006-12-12 17:49 - 2006-12-12 17:49 - 0000000 ____C () C:\Documents and Settings\Owner\Application Data\internaldb6334.dat 2006-12-12 17:49 - 2006-12-12 17:49 - 0009216 ____C () C:\Documents and Settings\Owner\Application Data\internaldb8467.dat C:\Documents and Settings\Owner\Local Settings\temp\AskSLib.dll EmptyTemp: end - Click File, Save As and type fixlist.txt as the File Name.
- Important: The file must be saved in the same location as FRST.exe.
NOTICE: This script is intended for use on this particular machine. Do not use this script on any other machine; doing so may cause damage to your Operating System.
- Double-Click FRST.exe to run the programme.
- Click Fix.
- A log (Fixlog.txt) will open on your desktop. Copy the contents of the log and paste in your next reply.
STEP 3
[external image: E3feWj5.png] Junkware Removal Tool (JRT)
- Please download Junkware Removal Tool and save the file to your Desktop.
- Create a System Restore Point. For instructions, please refer to the following link (XP).
- Temporarily disable your anti-virus software. For instructions, please refer to the following link.
- Double-Click JRT.exe to run the programme.
- Follow the prompts and allow the scan to run uninterrupted.
- Upon completion, a log (JRT.txt) will open on your desktop.
- Re-enable your anti-virus software.
- Copy the contents of JRT.txt and paste in your next reply.
STEP 4
[external image: BY4dvz9.png] AdwCleaner
- Please download AdwCleaner and save the file to your Desktop.
- Double-Click AdwCleaner.exe to run the programme.
- Follow the prompts.
- Click Scan.
- Upon completion, click Report. A log (AdwCleaner[R0].txt) will open. Briefly check the log for anything you know to be legitimate.
- Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
- Follow the prompts and allow your computer to reboot.
- After rebooting, a log (AdwCleaner[S0].txt) will open. Copy the contents of the log and paste in your next reply.
– File and folder backups are made for items removed using this tool. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.
======================================================
STEP 5
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.
- Did the programmes uninstall successfully?
- Fixlog.txt
- JRT.txt
- AdwCleaner[S0].txt
Hi Adam,
Yes, the programs you told me to uninstall with Revo uninstalled succesfully .
Here are the logs you asked for.
FRST Fixlog
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 11-03-2015
Ran by [removed] at 2015-03-23 19:59:18 Run:1
Running from C:\Documents and Settings\[removed]\My Documents\Anti-Virus
[removed]
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
start
CreateRestorePoint:
HKU\S-1-5-21-796845957-789336058-854245398-1003\…\Run: [OutfoxTV] => C:\Program Files\OutfoxTV\OutfoxTV\DesktopContainer.exe
C:\Program Files\OutfoxTV
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-796845957-789336058-854245398-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "http://www.outfox.tv/?referid="<=======ATTENTION
SearchScopes: HKLM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
SearchScopes: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> URL http://search.condui…rchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> SuggestionsURL_JSON http://suggest.searc…x={searchTerms}
SearchScopes: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.condui…rchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> {73EF2913-7B1D-4E29-A0BD-52D63C98462D} URL = http://search.yahoo….=utf-8&fr=b1ie7
BHO: WordExtra -> {8BA97046-C600-4264-B367-5DEFD9FC505F} -> C:\Documents and Settings\Owner\Application Data\WordExtra\temp.dat [2013-11-13] ()
C:\Documents and Settings\Owner\Application Data\WordExtra
Toolbar: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKU\S-1-5-21-796845957-789336058-854245398-1003 -> No Name - {41545534-2D56-3700-76A7-7A786E7484D7} - No File
FF SearchEngineOrder.1: Ask.com
FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\conduit-search.xml [2014-03-06]
S2 OutfoxTvService; C:\Program Files\OutfoxTV\OutfoxTvService.exe [X]
2006-12-12 17:48 - 2006-12-12 17:48 - 0000023 ____C () C:\Documents and Settings\Owner\Application Data\inifile41.ini
2006-12-12 17:48 - 2006-12-18 04:56 - 0000337 ____C () C:\Documents and Settings\Owner\Application Data\internaldb1942.dat
2006-12-12 17:49 - 2006-12-19 01:07 - 0000049 ____C () C:\Documents and Settings\Owner\Application Data\internaldb41.dat
2006-12-12 17:48 - 2006-12-12 17:49 - 0020480 ____C () C:\Documents and Settings\Owner\Application Data\internaldb4827.dat
2006-12-12 17:48 - 2006-12-12 17:48 - 0000000 ____C () C:\Documents and Settings\Owner\Application Data\internaldb5436.dat
2006-12-12 17:49 - 2006-12-12 17:49 - 0000000 ____C () C:\Documents and Settings\Owner\Application Data\internaldb6334.dat
2006-12-12 17:49 - 2006-12-12 17:49 - 0009216 ____C () C:\Documents and Settings\Owner\Application Data\internaldb8467.dat
C:\Documents and Settings\Owner\Local Settings\temp\AskSLib.dll
EmptyTemp:
end
*****************
Restore point was successfully created.
HKU\S-1-5-21-796845957-789336058-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Run\\OutfoxTV => value deleted successfully.
"C:\Program Files\OutfoxTV" => File/Directory not found.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKU\S-1-5-21-796845957-789336058-854245398-1003\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\\Tabs => Value was restored successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" => Key deleted successfully.
HKCR\CLSID\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} => Key not found.
HKU\S-1-5-21-796845957-789336058-854245398-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\URL => value deleted successfully.
HKU\S-1-5-21-796845957-789336058-854245398-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SuggestionsURL_JSON => value deleted successfully.
"HKU\S-1-5-21-796845957-789336058-854245398-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" => Key deleted successfully.
HKCR\CLSID\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} => Key not found.
"HKU\S-1-5-21-796845957-789336058-854245398-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{73EF2913-7B1D-4E29-A0BD-52D63C98462D}" => Key deleted successfully.
HKCR\CLSID\{73EF2913-7B1D-4E29-A0BD-52D63C98462D} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8BA97046-C600-4264-B367-5DEFD9FC505F} => Key not found.
HKCR\CLSID\{8BA97046-C600-4264-B367-5DEFD9FC505F} => Key not found.
"C:\Documents and Settings\Owner\Application Data\WordExtra" => File/Directory not found.
HKU\S-1-5-21-796845957-789336058-854245398-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} => value deleted successfully.
HKCR\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found.
HKU\S-1-5-21-796845957-789336058-854245398-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{41545534-2D56-3700-76A7-7A786E7484D7} => value deleted successfully.
HKCR\CLSID\{41545534-2D56-3700-76A7-7A786E7484D7} => Key not found.
Firefox SearchEngineOrder.1 deleted successfully.
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\conduit-search.xml => Moved successfully.
OutfoxTvService => Service deleted successfully.
C:\Documents and Settings\Owner\Application Data\inifile41.ini => Moved successfully.
C:\Documents and Settings\Owner\Application Data\internaldb1942.dat => Moved successfully.
C:\Documents and Settings\Owner\Application Data\internaldb41.dat => Moved successfully.
C:\Documents and Settings\Owner\Application Data\internaldb4827.dat => Moved successfully.
C:\Documents and Settings\Owner\Application Data\internaldb5436.dat => Moved successfully.
C:\Documents and Settings\Owner\Application Data\internaldb6334.dat => Moved successfully.
C:\Documents and Settings\Owner\Application Data\internaldb8467.dat => Moved successfully.
C:\Documents and Settings\Owner\Local Settings\temp\AskSLib.dll => Moved successfully.
EmptyTemp: => Removed 1.6 GB temporary data.
The system needed a reboot.
==== End of Fixlog 20:08:52 ====
JRT Log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.6 (03.22.2015:1)
OS: Microsoft Windows XP x86
Ran by [removed] on Mon 03/23/2015 at 20:43:30.12
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Toolbar.CT2438727
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{4E7BD74F-2B8D-469E-94BE-FD60BB9AAE2A}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{4E7BD74F-2B8D-469E-94BE-FD60BB9AAE2B}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT2438727
Successfully deleted: [Registry Key] "hkey_current_user\software\apn pip"
Successfully deleted: [Registry Key] "hkey_current_user\software\pip"
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
~~~ Files
Successfully deleted: [File] "C:\WINDOWS\wininit.ini"
~~~ Folders
Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\apn"
Successfully deleted: [Folder] "C:\Documents and Settings\Owner\Application Data\vshare"
Successfully deleted: [Folder] "C:\Program Files\eusing free registry cleaner"
Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\ask"
Successfully deleted: [Folder] "C:\Program Files\ask.com"
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 03/23/2015 at 20:58:16.20
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
AdwCleaner[S0] Log
# AdwCleaner v4.113 - Logfile created 23/03/2015 at 21:56:31
# Updated 22/03/2015 by Xplode
# Database : 2015-03-23.1 [Server]
# Operating system : Microsoft Windows XP Service Pack 3 (x86)
# Username : Owner - OWNER-XUKSZMPNK
# Running from : C:\Documents and Settings\Owner\Desktop\AdwCleaner.exe
# Option : Cleaning
***** [ Services ] *****
Service Deleted : YahooAUService
***** [ Files / Folders ] *****
Folder Deleted : C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
File Deleted : C:\END
File Deleted : C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\user.js
***** [ Scheduled tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\conduit.com
Key Deleted : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Key Deleted : HKLM\SOFTWARE\Classes\TotalRecipeSearch_14Installer.Start
Key Deleted : HKLM\SOFTWARE\Classes\TotalRecipeSearch_14Installer.Start.1
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@ei.TotalRecipeSearch_14.com/Plugin
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\ask.com
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search\ask.com
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B3EAD50C-ECB0-459A-9EDA-F505AB99675B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD79F359-E577-46DB-AA74-D6E6B8B45BA8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1A1BBE49-C6F1-40EA-9D2F-262F0AF6DDE3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2022154E-7E3E-4809-871E-1B45A6FC7058}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{20ED5AF7-D9C4-409E-9EB3-D2A44A77FB6D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{292ECB89-350E-45D2-816F-52C15305B144}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{36CC2180-B6BF-4951-9578-6B0C40044AAA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3B181CF2-878B-4758-8FBD-59D8AC5AB12D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{44A36944-22C6-4A08-BC7C-161F3E540DBF}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{490A5A0F-1471-47FF-8BB5-719F1F5238AD}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6247DD2C-8CF9-4041-A235-93691D71B8B4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{835BED79-DF7E-4096-B355-ED43FA2EA87B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C953EC4-8CFA-44FB-B32E-1249E5505091}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8E863BD6-50DE-47D0-A6F1-3C1F6DB72451}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9DD36F1E-5111-41C5-ADED-A2A11A2FF3E4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A2FB8217-E320-434E-BA79-513E357AD54F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9CEBBF4-9129-479A-9231-E833ED3D3A8F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AFD4D1F9-167C-4884-95AE-B5A9797B0D16}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B3EAD50C-ECB0-459A-9EDA-F505AB99675B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C47788B1-9604-4D7A-A684-F4D450F2D7D2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{CA3B41D0-D4C1-4808-B248-75DA27238828}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D4A2FF6C-087F-4D40-8DFE-92AAD484BFB8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D88B9D5C-A9CF-4C69-906D-1CCA5D85A2EF}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F83AF01C-AA2F-469F-8BE7-D178FB15FD07}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8E5B29C2-BC6E-40BE-B881-AEE35B1F4035}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7B13EC3E-999A-4B70-B9CB-2617B8323822}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3B7599DF-3D5D-4EF5-BF51-9C2EDA788E83}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FD79F359-E577-46DB-AA74-D6E6B8B45BA8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4250488A-CB24-0893-C066-B1AEA57BCFF2}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}]
Key Deleted : HKCU\Software\Alexa Internet
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\Zugo
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\AskSA
Key Deleted : HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\ConduitToolbar
Key Deleted : HKLM\SOFTWARE\ImInstaller
Key Deleted : HKLM\SOFTWARE\PIP
Key Deleted : HKLM\SOFTWARE\TotalRecipeSearch_14EI
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Companion
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Yahoo! Companion
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
***** [ Web browsers ] *****
-\\ Internet Explorer v8.0.6001.18702
-\\ Mozilla Firefox v36.0.4 (x86 en-US)
*************************
AdwCleaner[R0].txt - [7035 bytes] - [23/03/2015 21:12:06]
AdwCleaner[R1].txt - [7094 bytes] - [23/03/2015 21:29:02]
AdwCleaner[S0].txt - [7169 bytes] - [23/03/2015 21:56:31]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7228 bytes] ##########
That's it, I seriously appreciate you taking time to help me with this. Let me know what the next step is.
Hi Juan,
I seriously appreciate you taking time to help me with this. Let me know what the next step is.
That's quite alright.
How is your computer performing? Are you experiencing any outstanding issues?
Lets check for remnants.
STEP 1
[external image: x6YRrgUC.png.pagespeed.ic.HjgFxjvw2Z.jpg] MBAM Clean
- Please read the following article on how to run MBAM Clean.
- (!) Ensure you follow the correct set of instructions depending on which version you have (Free or Premium).
STEP 2
[external image: GfiJrQ9.png] Malwarebytes Anti-Malware (MBAM)
- Please download the Malwarebytes Anti-Malware setup file to your Desktop.
- Open mbam-setup.x.x.xxxx.exe (x represents the version #) and follow the prompts to install the programme.
- Open Malwarebytes Anti-Malware and click Update Now.
- Once updated, click the Settings tab, followed by Detection and Protection and tick Scan for rootkits.
- Click the Scan tab, ensure Threat Scan is selected and click Start Scan.
- Note: You may see the following message, "Could not load DDA driver". Click Yes, allow your PC to reboot and continue afterwards.
- If threats are detected, click Remove Selected. If you are prompted to reboot, click Yes.
- Upon completion of the scan (or after the reboot), click the History tab.
- Click Application Logs and double-click the Scan Log.
- Click Copy to Clipboard and paste the log in your next reply.
STEP 3
[external image: GzlsbnV.png] ESET Online Scan
Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.
- Please download ESET Online Scan and save the file to your Desktop.
- Temporarily disable your anti-virus software. For instructions, please refer to the following link.
- Double-click esetsmartinstaller_enu.exe to run the programme.
- Agree to the EULA by placing a checkmark next to Yes, I accept the Terms of Use. Then click Start.
- Agree to the Terms of Use once more and click Start. Allow components to download.
- Place a checkmark next to Enable detection of potentially unwanted applications.
- Click Advanced settings. Place a checkmark next to:
- Scan archives
- Scan for potentially unsafe applications
- Enable Anti-Stealth technology
- Ensure Remove found threats is unchecked.
- Click Start.
- Wait for the scan to finish. Please be patient as this can take some time.
- Upon completion, click [external image: esetListThreats.png]. If no threats were found, skip the next two bullet points.
- Click [external image: esetExport.png] and save the file to your Desktop, naming it something such as "MyEsetScan".
- Push the Back button.
- Place a checkmark next to [external image: xKN1w2nv.png.pagespeed.ic.JWqIaEgZi7.png] and click [external image: SzOC1p0.png.pagespeed.ce.OWDP45O6oG.png].
- Re-enable your anti-virus software.
- Copy the contents of the log and paste in your next reply.
STEP 4
[external image: mlEX1wH.png] RogueKiller
- Please download RogueKiller (x32) and save the file to your Desktop.
- Close any running programmes.
- Double-Click RogueKiller.exe to run the programme.
- Allow the Prescan to complete. Upon completion, a window will open. Click Accept.
- A browser window may open. Close the browser window.
- Click [external image: jpgUwzp.png]. Upon completion, click [external image: phPvmc6.png].
- Close the programme. Do not fix anything!
- A log (RKreport.txt) will be open. Copy the contents of the log and paste in your next reply.
======================================================
STEP 5
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.
- Did MBAM Clean run successfully?
- MBAM Scan log
- ESET Online Scan log
- RKreport.txt
Hello Adam, hope your day is going good.
Here are the logs you had asked for, MBAM Clean ran smoothly.
==================================================
MBAM Log
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 3/24/2015
Scan Time: 5:48:26 AM
Logfile: MBMA Log.txt
Administrator: Yes
Version: 2.01.4.1018
Malware Database: v2015.03.24.03
Rootkit Database: v2015.02.25.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows XP Service Pack 3
CPU: x86
File System: NTFS
User: Owner
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 368984
Time Elapsed: 1 hr, 5 min, 17 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
==================================================
++++++++++++++++++++++++++++++++++++++++++++++++++
ESET Log
C:\Documents and Settings\Owner\My Documents\APNSetup1.exe a variant of Win32/Bundled.Toolbar.Ask.E potentially unsafe application
C:\FRST\Quarantine\C\Documents and Settings\Owner\Local Settings\temp\AskSLib.dll.xBAD a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application
C:\System Volume Information\_restore{3454468E-9477-4148-B1AC-26ED7ED7F8F0}\RP1007\A0104845.dll a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application
C:\System Volume Information\_restore{3454468E-9477-4148-B1AC-26ED7ED7F8F0}\RP993\A0101115.exe a variant of Win32/InstallCore.VM potentially unwanted application
C:\System Volume Information\_restore{3454468E-9477-4148-B1AC-26ED7ED7F8F0}\RP993\A0101116.exe a variant of Win32/InstallCore.VM potentially unwanted application
C:\System Volume Information\_restore{3454468E-9477-4148-B1AC-26ED7ED7F8F0}\RP999\A0103716.dll a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application
C:\System Volume Information\_restore{3454468E-9477-4148-B1AC-26ED7ED7F8F0}\RP999\A0103717.exe a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application
C:\System Volume Information\_restore{3454468E-9477-4148-B1AC-26ED7ED7F8F0}\RP999\A0103718.exe a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application
C:\WINDOWS\system32\Adobe\Shockwave 12\gt.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application
++++++++++++++++++++++++++++++++++++++++++++++++++
==================================================
RK Log
RogueKiller V10.5.7.0 [Mar 22 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Owner [Administrator]
Started from : C:\Documents and Settings\Owner\Desktop\RogueKiller.exe
Mode : Scan – Date : 03/24/2015 15:11:33
¤¤¤ Processes : 1 ¤¤¤
[Suspicious.Path] explorer.exe(1144) – C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Hook\rndlchrome10browserrecordhelper.dll[7] -> Unloaded
¤¤¤ Registry : 1 ¤¤¤
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Found
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ Hosts File : 1 ¤¤¤
[C:\WINDOWS\system32\drivers\etc\hosts] 127.0.0.1 localhost
¤¤¤ Antirootkit : 2 (Driver: Loaded) ¤¤¤
[ShwSSDT:Addr(Hook.Shadow)] NtUserSetWindowsHookEx[549] : Unknown @ 0xf8117906
[ShwSSDT:Addr(Hook.Shadow)] NtUserSetWinEventHook[552] : Unknown @ 0xf811790b
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: ST3120814A +++++
— User —
[MBR] bb516b866514ee8d45f67e63117250ee
[BSP] 4416934579fef884f265f75abf1c1bc2 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 114463 MB [Windows XP Bootstrap | Windows XP Bootloader]
User = LL1 … OK
User = LL2 … OK
==================================================
Have a good day!!
Hello Juan,
Please delete this file (Right-Click + Delete): C:\Documents and Settings\Owner\My Documents\APNSetup1.exe
Right-Click your Recycle Bin afterwards and click Empty.
How is your computer performing? Are you experiencing any outstanding issues?
Hi Adam,
I deleted the file you told me to. My PC seems to be running smoothly, and I haven't gotten any warnings from Avira.
I have a question though, is it safe to plug in the iPod now and try to reformat? And do you know of a way I can do this?
I know the iPod has to be in FAT32, and since I run on XP it won't let me format it 'cause it's the 180GB version. :/
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI